How to turn on WordPress automatic updates

Most hacked WordPress sites were running an outdated plugin. Automatic updates close that gap. You can turn them on inside WordPress, or manage them from your control panel with a backup taken before each update.

Option 1: Inside WordPress

Core

  1. Go to Dashboard → Updates.
  2. Click Enable automatic updates for all new versions of WordPress.

By default WordPress installs minor (security) releases on its own. This switches on major releases too.

Plugins

  1. Go to Plugins → Installed Plugins.
  2. In the Automatic Updates column, click Enable auto-updates next to each plugin.
  3. Or tick several plugins, choose Enable Auto-updates from Bulk actions, and click Apply.

Themes

  1. Go to Appearance → Themes.
  2. Click a theme to open its details.
  3. Click Enable auto-updates.

Do this for the active theme and its parent theme if you use a child theme.

If updates have been switched off

If you find define( 'AUTOMATIC_UPDATER_DISABLED', true ); in wp-config.php, remove it. Adding define( 'WP_AUTO_UPDATE_CORE', true ); above /* That's all, stop editing! */ turns core updates back on.

Option 2: Softaculous

Softaculous can update core, plugins and themes and take a backup first.

  1. Open it:
    • cPanel: Softaculous Apps Installer, or WordPress Manager by Softaculous if shown.
    • DirectAdmin: Extra Features → WordPress Manager by Softaculous.
  2. Find your site and open its settings.
  3. Under the auto-upgrade options, choose whether to upgrade WordPress to any new version or to minor versions only.
  4. Turn on automatic upgrades for plugins and themes.
  5. Turn on the backup-before-upgrade option, if shown, so a bad update can be rolled back.
  6. Save.

Softaculous only manages sites it installed or that you've imported into it.

Option 3: WP Toolkit (most cPanel servers)

  1. In cPanel, open WP Toolkit. If you don't see it, use Softaculous or open a ticket.
  2. Open your site's update settings.
  3. Set WordPress core, plugins and themes to update automatically.
  4. Save.

Use one manager, not two. If Softaculous and WP Toolkit both auto-update the same site, they'll get in each other's way.

Make sure updates actually run

WordPress runs updates from its internal scheduler, which only fires when someone visits the site. A quiet site can go days without an update check. Fix that with a real cron job:

  1. Add this to wp-config.php:

    define( 'DISABLE_WP_CRON', true );
    
  2. Create a cron job that runs every 15 minutes:

    */15 * * * * wget -q -O - https://example.co.za/wp-cron.php?doing_wp_cron >/dev/null 2>&1
    

See How to set up a cron job.

When updates go wrong

  • Site broken after an update: restore the backup from Softaculous or WP Toolkit, or rename the plugin's folder in wp-content/plugins to disable it. See WordPress shows "There has been a critical error" or a white screen.
  • "Another update is currently in progress": wait 15 minutes; WordPress clears the lock itself.
  • "Could not create directory": file permissions. Folders should be 755, files 644.
  • Paid plugins don't update: their licence key must be entered and valid.

Did this answer it?